A PHP External Variable Modification vulnerability in J...
Critical severity
Unreviewed
Published
Aug 17, 2023
to the GitHub Advisory Database
•
Updated Feb 11, 2024
Description
Published by the National Vulnerability Database
Aug 17, 2023
Published to the GitHub Advisory Database
Aug 17, 2023
Last updated
Feb 11, 2024
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series
and SRX Series
allows an unauthenticated, network-based attacker to control certain, important environments variables.
Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on SRX Series:
prior to
22.1R3-S4;
prior to
22.2R3-S2;
prior to
22.3R2-S2, 22.3R3-S1;
prior to
22.4R2-S1, 22.4R3;
References